The AICPA’s Peer Review Board issued a reviewer alert in May 2026 telling peer reviewers how to handle firms performing high-volume SOC 2 engagements on third-party compliance platforms. The specific failure it names is engagements that produce identical reports, risk assessments, sample sizes and testing procedures across different clients. In peer review terms those are nonconforming: not performed in accordance with professional standards in all material respects. From 1 June 2026, firms with SOC 2 practices are identified for structured monitoring. If you are buying a SOC 2 audit, this changes what you should ask before you sign.
Most coverage of SOC 2 is written for the company being audited. This one is about the auditors, which is why it matters to you: it tells you what their own regulator has decided is not good enough.
Everything below is quoted from the Journal of Accountancy’s report, which is the AICPA’s own publication.
What the AICPA actually said
Carl Mayes, CPA, the AICPA’s vice president for Ethics and Firm Quality:
Some firms are leaning too heavily on third-party SOC platforms without applying the professional judgment required by our standards. Regardless of the tools used, CPAs must remain competent, objective, independent, and committed to engagements that reflect the unique risks and circumstances of each client.
And the failure pattern, stated precisely:
One specific risk is that a firm’s SOC 2 engagements are not designed to respond to the unique risks associated with the service organization, resulting in engagements that have identical reports, risk assessments, sample sizes, and testing procedures. In such circumstances, these engagements are not performed in accordance with the relevant professional standards in all material respects. In peer review, this is known as a “nonconforming” engagement.
Read that second quote slowly. The problem is not that a firm used software. The problem is that the output was the same for every client, which is evidence the engagement was never designed for any of them.
What “nonconforming” costs the firm
A nonconforming conclusion is not a note in a file. It increases the likelihood that the firm carries a deficiency or significant deficiency in its peer review report, and that it has to complete a follow-up action: revising its system of quality management, or having an outside party review completed engagements.
That is a real consequence for the firm, and it is the reason this alert has teeth rather than being guidance nobody acts on.
The five-report test
The part worth knowing as a buyer is how reviewers are now told to look. Where elevated risk is identified, the response may include:
- Selecting several SOC 2 engagements, often about five, from different partners
- Comparing those reports to one another and to prior-year reports
- Reviewing targeted areas that require engagement-specific judgment
- Determining whether identical risk assessments, control designs, sample sizes, or testing procedures appear across engagements
Reviewers are also guided to understand the firm’s use of technology including external SOC platforms, the reasonableness of engagement timelines, and whether engagements are tailored to each client’s environment.
The timelines line is the one that should make a buyer pause. A quoted turnaround that seems impressively short is now something the auditor’s own regulator treats as a risk indicator.
What this does not mean
Three clarifications, because this is being misread already.
It is not a finding against compliance platforms. The alert addresses how some firms use them. A platform can be part of a well-run engagement. What fails is a firm substituting the tool for its own judgement. If you are running Vanta, Drata or a comparable platform, nothing here says you chose wrong.
It does not make your existing report invalid. Peer review examines the firm’s practice. It is not a recall of issued reports.
It does not apply to penetration testing vendors. AICPA peer review governs CPA firms performing the SOC 2 examination. We are not a CPA firm, we do not perform or sign the examination, and we refer that work to a CPA partner. Anyone in our line of business presenting this alert as vindication of themselves is doing the thing the alert is about.
Four questions to ask your auditor
All four are answerable in writing, and a firm running a tailored engagement will not find them difficult.
- When was your last peer review, and what was the result? Peer review results are a matter of record. A firm that will not discuss it is telling you something.
- How does the risk assessment for our engagement differ from the last client you did in our industry? You are not asking for their client’s details. You are asking whether a risk assessment happened.
- What determined our sample sizes? “The platform’s default” is an answer, and it is the one the alert is about.
- Which parts of this engagement run on a platform, and which involve your own testing? A good firm answers this happily, because the split is the value they add.
The principle, which travels further than the jurisdiction
Strip away who it governs and the alert says something simple: a deliverable that is identical across different clients was not designed for any of them.
That is worth holding onto beyond SOC 2, because it is the same test a buyer should apply to a penetration test report. If two companies with different architectures, different user roles and different data receive reports with the same findings in the same order, the report describes the tool that produced it rather than the system it was pointed at. That is why we publish our sample report in full, with the reproduction steps and the client-specific business impact visible, rather than describing it.
The AICPA has now written that principle down for auditors. It was always true of assurance work generally.
Where we fit, stated plainly
We produce the penetration test and the report that goes into your SOC 2 evidence package, with each finding mapped to the Trust Services Criteria. We do not perform the examination, we do not issue the opinion, and the CPA partner does that work. If you want the detail of how the mapping works, our audit and compliance readiness page covers it, and our SOC 2 Trust Services Criteria explainer covers the criteria themselves.
The reason to read this alert is not to pick a pentest vendor. It is to ask better questions of whoever signs your report.
Sources
- AICPA guides peer reviewers to address SOC 2 risks, Journal of Accountancy, May 2026. All quotations above are from this report.
- 2017 Trust Services Criteria (With Revised Points of Focus, 2022), AICPA. The criteria a SOC 2 examination is performed against, and still the current edition as of August 2026.
- The article also references “SOC Engagements: Ethics Risks With Tool Providers” (Journal of Accountancy, 6 April 2026) and a podcast episode, “The Risks of Quick-Turn SOC Engagements and What CPAs Should Know” (30 April 2026).